Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Bedework jsforj: Support for JSCalendar/JSContacts

org.bedework:bw-jsforj:2.1.0-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
bw-base-2.0.0.jarpkg:maven/org.bedework/bw-base@2.0.0 042
bw-util-caching-6.0.1.jarpkg:maven/org.bedework/bw-util-caching@6.0.1 044
bw-util-config-6.0.0.jarpkg:maven/org.bedework/bw-util-config@6.0.0 044
bw-util-http-6.1.0-SNAPSHOT.jarpkg:maven/org.bedework/bw-util-http@6.1.0-20250924.033026-2
pkg:maven/org.bedework/bw-util-http@6.1.0-SNAPSHOT
 043
bw-util-jmx-6.0.0.jarpkg:maven/org.bedework/bw-util-jmx@6.0.0 044
bw-util-logging-6.0.0.jarpkg:maven/org.bedework/bw-util-logging@6.0.0 044
bw-util-misc-6.0.1.jarcpe:2.3:a:utils_project:utils:6.0.1:*:*:*:*:*:*:*pkg:maven/org.bedework/bw-util-misc@6.0.1 0Low44
bw-util-tz-6.0.2.jarpkg:maven/org.bedework/bw-util-tz@6.0.2 042
bw-util-xml-6.0.1.jarpkg:maven/org.bedework/bw-util-xml@6.0.1 044
commons-codec-1.17.1.jarpkg:maven/commons-codec/commons-codec@1.17.1 0121
commons-lang3-3.18.0.jarcpe:2.3:a:apache:commons_lang:3.18.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-lang3@3.18.0 0Highest145
commons-logging-1.2.jarpkg:maven/commons-logging/commons-logging@1.2 0117
commons-text-1.14.0.jarcpe:2.3:a:apache:commons_text:1.14.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-text@1.14.0 0Highest73
httpclient-4.5.14.jarcpe:2.3:a:apache:httpclient:4.5.14:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 0Highest32
httpcore-4.4.16.jarpkg:maven/org.apache.httpcomponents/httpcore@4.4.16 032
ical4j-3.0.24.jarpkg:maven/org.bedework.ical4j/ical4j@3.0.24 038
jackson-core-2.18.2.jarcpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.2 0Low47
jackson-databind-2.18.2.jarcpe:2.3:a:fasterxml:jackson-databind:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2 0Highest41
jakarta.activation-api-2.1.3.jarpkg:maven/jakarta.activation/jakarta.activation-api@2.1.3 045
jakarta.mail-api-2.1.3.jarcpe:2.3:a:eclipse:jakarta_mail:2.1.3:*:*:*:*:*:*:*pkg:maven/jakarta.mail/jakarta.mail-api@2.1.3 0High36
slf4j-api-1.7.36.jarpkg:maven/org.slf4j/slf4j-api@1.7.36 029

Dependencies (vulnerable)

bw-base-2.0.0.jar

Description:

This project provides base classes, types and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-base/2.0.0/bw-base-2.0.0.jar
MD5: 0480624145ad4fc5daeba898b7132099
SHA1: b24b7279e0475bb3c8c84e37af400ad87877c955
SHA256:10d27642e3bf1f2f4f85320293b5041b7e34cba02cc2656f29e79f75cee97cc5
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-base-2.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

bw-util-caching-6.0.1.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-caching/6.0.1/bw-util-caching-6.0.1.jar
MD5: 770d86792dd9af90cec290f40686e6b5
SHA1: 39d385d0b54d02a41d3d7f551814702968d094e6
SHA256:ee77ea34a8fbea0cc9303d57e474f281993509663c25dcf1074207d0ea908c7d
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-caching-6.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

bw-util-config-6.0.0.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-config/6.0.0/bw-util-config-6.0.0.jar
MD5: 974d4ee4953df439fc3753869cc469da
SHA1: c1f787f23f0c5028280a457d0709418ea332fe09
SHA256:97ee0ce50094f85f881d63fb423dfb7ae1973843ac6028f0488860394553aa60
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-config-6.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

bw-util-http-6.1.0-SNAPSHOT.jar

Description:

Network (http, DAV,servlet etc) related utilities

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-http/6.1.0-SNAPSHOT/bw-util-http-6.1.0-SNAPSHOT.jar
MD5: 002c7131ae25ebe36760372099e79140
SHA1: 1f92c754599340fb829faf062a4ca5887ffef28b
SHA256:619a9bef9a7469edf73f09ef7627fe4662edfae8583c52ffccf1d8e326430cf3
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-http-6.1.0-SNAPSHOT.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

bw-util-jmx-6.0.0.jar

Description:

This project provides a number of utility configuration classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-jmx/6.0.0/bw-util-jmx-6.0.0.jar
MD5: e7ffae94c51d5c62aa657c7f321607b5
SHA1: cbfbb6e89fa5adac492adcc48866cfec62cc932d
SHA256:60b3d4ce24901fc1ab0b741be3413efaffb263f99f368062618478c67e7fd3b9
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-jmx-6.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

bw-util-logging-6.0.0.jar

Description:

This project provides logging utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-logging/6.0.0/bw-util-logging-6.0.0.jar
MD5: 2c63b9031e2d0852a00e57753320b409
SHA1: a12c15e6670f1298c8c4779d08b24595e921aceb
SHA256:e26bbaf5a5dcad998990fdc647f448b2e2dcac6eb628be6945fe24d53759b745
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-logging-6.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

bw-util-misc-6.0.1.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-misc/6.0.1/bw-util-misc-6.0.1.jar
MD5: 9dc0272f11c9a1803a160354fe2e5872
SHA1: 905462b918aab23efb8940c4270f3c087870c784
SHA256:7662745dcbbeddcb3f15e2db9ffd5cfa9fe1c55a015b378f99cde1de5dcfe0e4
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-misc-6.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

bw-util-tz-6.0.2.jar

Description:

Timezone utility classes

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-tz/6.0.2/bw-util-tz-6.0.2.jar
MD5: e6f6ed3f3fc6fb4f4f7b1bf873dd932b
SHA1: d588ba81e03413eba42b77bba5de5171182c2c91
SHA256:c310a597eac84e6091f015bcc5bbbd02d8e28a037a13ba8291e48a6c43c41577
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-tz-6.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

bw-util-xml-6.0.1.jar

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-xml/6.0.1/bw-util-xml-6.0.1.jar
MD5: f8c1e22fbcf5ed35bed2faaa7906d70e
SHA1: fef45c09a64cd5eec4530db96892192e14abb286
SHA256:9ca8659400a0840d0e889f604f1e0d7ea139ed7486116e54dfb8e94be39ffa32
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
bw-util-xml-6.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

commons-codec-1.17.1.jar

Description:

     The Apache Commons Codec component contains encoders and decoders for
     various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-codec/commons-codec/1.17.1/commons-codec-1.17.1.jar
MD5: 7b3438ab4c6d91e0066d410947e43f3e
SHA1: 973638b7149d333563584137ebf13a691bb60579
SHA256:f9f6cb103f2ddc3c99a9d80ada2ae7bf0685111fd6bffccb72033d1da4e6ff23
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
commons-codec-1.17.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

commons-lang3-3.18.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17 and 21 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.18.0/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256:4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

commons-logging-1.2.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256:daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
commons-logging-1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

commons-text-1.14.0.jar

Description:

Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256:121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
commons-text-1.14.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-misc@6.0.1

Identifiers

httpclient-4.5.14.jar

Description:

   Apache HttpComponents Client
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jar
MD5: 2cb357c4b763f47e58af6cad47df6ba3
SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98
SHA256:c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
httpclient-4.5.14.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

httpcore-4.4.16.jar

Description:

   Apache HttpComponents Core (blocking I/O)
  

File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jar
MD5: 28d2cd9bf8789fd2ec774fb88436ebd1
SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850
SHA256:6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
httpcore-4.4.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

ical4j-3.0.24.jar

Description:

A Java library for reading and writing iCalendar (*.ics) files

License:

BSD 3-Clause License: https://github.com/ical4j/ical4j/raw/refs/heads/develop/LICENSE.txt
File Path: /home/runner/.m2/repository/org/bedework/ical4j/ical4j/3.0.24/ical4j-3.0.24.jar
MD5: 8a13d47cb0406201477c9ebbd54d9a27
SHA1: d1aef2a3d985edbf59726889a1ff0adc18b20122
SHA256:042344cb9f0bd8429ba6a14a8f4d9c4486dbdd739e852539a42c7baff50614ff
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
ical4j-3.0.24.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

jackson-core-2.18.2.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.2/jackson-core-2.18.2.jar
MD5: bf935e6eca3a57defa13918661905cb0
SHA1: fb64ccac5c27dca8819418eb4e443a9f496d9ee7
SHA256:d8054ae7c0d1c2d2f55d28e46026ebe5892881f3fab5f439233184381c3b4a1f
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
jackson-core-2.18.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

jackson-databind-2.18.2.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.18.2/jackson-databind-2.18.2.jar
MD5: 1b56887bcd3eaea1ff710eb673e610b0
SHA1: deef8697b92141fb6caf7aa86966cff4eec9b04f
SHA256:4b364e6850dc89172fcf1d4dd26b8ff5488eda44ff4657e22dd265203dd5ab3c
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
jackson-databind-2.18.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-jsforj@2.1.0-SNAPSHOT

Identifiers

jakarta.activation-api-2.1.3.jar

Description:

  Specification

License:

EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/runner/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.3/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256:01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
jakarta.activation-api-2.1.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

jakarta.mail-api-2.1.3.jar

Description:

  Specification API

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/runner/.m2/repository/jakarta/mail/jakarta.mail-api/2.1.3/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256:8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
jakarta.mail-api-2.1.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-tz@6.0.2

Identifiers

slf4j-api-1.7.36.jar

Description:

The slf4j API

File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jar
MD5: 872da51f5de7f3923da4de871d57fd85
SHA1: 6c62681a2f655b49963a5983b8b0950a6120ae14
SHA256:d3ef575e3e4979678dc01bf1dcce51021493b4d11fb7f1be8ad982877c16a1c0
Referenced In Project/Scope: Bedework jsforj: Support for JSCalendar/JSContacts:compile
slf4j-api-1.7.36.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.logging.log4j/log4j-slf4j-impl@2.23.1

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.